-

CVE-2026-68351

wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read

In the Linux kernel, the following vulnerability has been resolved:

wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read

When the firmware sends a command response with a length mismatch,
carl9170_cmd_callback() logs the mismatch and calls carl9170_restart()
but then falls through to memcpy(ar->readbuf, buffer + 4, len - 4).
Since len comes from the firmware and can exceed ar->readlen, this
copies more data than the readbuf was allocated for.

Bound the memcpy to min(len - 4, ar->readlen) so that the response
is still completed -- avoiding repeated restarts from queued garbage --
while preventing an overread past the response buffer.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version a84fab3cbfdc427e7d366f1cc844f27b2084c26c
Version < 38e240996a6a78c94ab07d461fd66e361d55c3c4
Status affected
Version a84fab3cbfdc427e7d366f1cc844f27b2084c26c
Version < 2d05c321d27624c413c950278d2dc8e0f44a8950
Status affected
Version a84fab3cbfdc427e7d366f1cc844f27b2084c26c
Version < 525036b20ef01d814a7fcd0567d123992e4479fa
Status affected
Version a84fab3cbfdc427e7d366f1cc844f27b2084c26c
Version < f74e34e66379e487a09009a4f2d42470051672bd
Status affected
Version a84fab3cbfdc427e7d366f1cc844f27b2084c26c
Version < 500c36649f270de05a56591fcc1aaaa36687958e
Status affected
Version a84fab3cbfdc427e7d366f1cc844f27b2084c26c
Version < 9aee949c68dc6dccbc54333537b109c53fe2079f
Status affected
Version a84fab3cbfdc427e7d366f1cc844f27b2084c26c
Version < cb7a38810cf25738176dac32dec7a146b3f959cf
Status affected
Version a84fab3cbfdc427e7d366f1cc844f27b2084c26c
Version < 4cde55b2feff9504d1f993ab80e84e7ccb62791c
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.37
Status affected
Version 0
Version < 2.6.37
Status unaffected
Version <= 5.10.*
Version 5.10.265
Status unaffected
Version <= 5.15.*
Version 5.15.216
Status unaffected
Version <= 6.1.*
Version 6.1.183
Status unaffected
Version <= 6.6.*
Version 6.6.148
Status unaffected
Version <= 6.12.*
Version 6.12.101
Status unaffected
Version <= 6.18.*
Version 6.18.42
Status unaffected
Version <= 7.1.*
Version 7.1.6
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.127
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/f74e34e66379e487a09009a4f2d42470051672bd
https://git.kernel.org/stable/c/500c36649f270de05a56591fcc1aaaa36687958e
https://git.kernel.org/stable/c/9aee949c68dc6dccbc54333537b109c53fe2079f
https://git.kernel.org/stable/c/cb7a38810cf25738176dac32dec7a146b3f959cf
https://git.kernel.org/stable/c/4cde55b2feff9504d1f993ab80e84e7ccb62791c
https://git.kernel.org/stable/c/2d05c321d27624c413c950278d2dc8e0f44a8950
https://git.kernel.org/stable/c/38e240996a6a78c94ab07d461fd66e361d55c3c4
https://git.kernel.org/stable/c/525036b20ef01d814a7fcd0567d123992e4479fa